Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243458

Re: debian.org/security is wrong to say what it does

From "Andrew M.A. Cater" <amacater@einval.com>
Newsgroups linux.debian.user
Subject Re: debian.org/security is wrong to say what it does
Date 2021-12-26 13:30 +0100
Message-ID <DyAOZ-pb-1@gated-at.bofh.it> (permalink)
References <Dy20V-4Em-1@gated-at.bofh.it> <DyeOt-3Ig-3@gated-at.bofh.it> <Dygnf-4Im-1@gated-at.bofh.it> <Dyob8-13S-5@gated-at.bofh.it> <DypAd-22L-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Sun, Dec 26, 2021 at 01:19:53AM +0100, maxwillb wrote:
> December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:
> 
> > So you're raising issues that everyone knows but can't do a great deal about given the difficulties
> 
> I hate to be a broken record, but you could edit https://www.debian.org/security/  so that it
> does not say "We handle all security problems brought to our attention and ensure that they
> are corrected within a reasonable timeframe. " and add a link to 
> https://security-tracker.debian.org/tracker/status/release/stable instead.
> 
> Even though it does not allow you to filter vulnerabilities by severity, it is better than nothing.
> 
> Merry Christmas!
> 

Hi,

I hate to be a broken record but - the best information you have is
from the security bug tracker and, as it says, this is based on source
packages, not necessarily binaries built from that.

It's also explicitly noted as being
based from unstable - if fixes go in there, they are recorded and prior
releases are marked as vulnerable - fixes and backports happen -but
that doesn't mean that everything marked as vulnerable is still at 
risk.

It's also true to say that some people still run oldstable and would be
interested in vulnerabilities there for example.

[There's a reason I keep on about keeping yourself up to date / running the
latest stable release in this list: I (and others) also point out the 
experience that is needed if you want to run testing / unstable and the
relative level of security support.]

If you're unhappy with data presentation, feel free to contact the security
team

Andy Cater

> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 00:20 +0100
  Re: How to see the list of CRITICALLY vulnerable packages in Debian? Dan Ritter <dsr@randomstring.org> - 2021-12-25 13:50 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:20 +0100
  Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-25 14:00 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 15:40 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-26 00:00 +0100
        Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:10 +0100
      debian.org/security is wrong to say what it does maxwillb  <maxwillb@mailfence.com> - 2021-12-26 01:30 +0100
        Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:30 +0100
          Re: debian.org/security is wrong to say what it does maxwillb  <maxwillb@mailfence.com> - 2021-12-26 21:40 +0100
            Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 23:00 +0100
  Re: How to see the list of CRITICALLY vulnerable packages in Debian? Andy Smith <andy@strugglers.net> - 2021-12-25 16:10 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:00 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:20 +0100
        Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:40 +0100
          Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:50 +0100
            Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 18:50 +0100

csiph-web